Moved inline comment.
Brian Vaughn committed
Sep 11, 2019 at 09:30 UTC
f09854a9e85cb612f26172f6ea1dea0b3de45aec
1 file changed
+3
-5
packages/react-devtools-extensions/src/injectGlobalHook.js
+3
-5
@@ -31,12 +31,10 @@ window.addEventListener('message', function(evt) {
31
reactBuildType: evt.data.reactBuildType,
32
};
33
chrome.runtime.sendMessage(lastDetectionResult);
34
-
35
- // Inject the backend. This is done in the content script to avoid CSP
36
- // and Trusted Types violations, since content scripts can modify the DOM
37
- // and are not subject to the page's policies.
34
} else if (evt.data.source === 'react-devtools-inject-backend') {
39
- // the prototype stuff is in case document.createElement has been modified
35
+ // The backend is injected by the content script to avoid CSP and Trusted Types violations,
36
+ // since content scripts can modify the DOM and are not subject to the page's policies.
37
+ // The prototype stuff is in case document.createElement has been modified.
38
const script = document.constructor.prototype.createElement.call(
39
document,
40
'script',